5
CVSSv2

CVE-1999-0414

Published: 01/03/1999 Updated: 17/08/2022
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

In Linux before version 2.0.36, remote attackers can spoof a TCP connection and pass data to the application layer before fully establishing the connection.

Vulnerable Product Search on Vulmon Subscribe to Product

linux linux kernel 2.0.30

linux linux kernel 2.0.37

linux linux kernel 2.0.36

linux linux kernel 2.0.35

Exploits

/* source: wwwsecurityfocuscom/bid/580/info Certain Linux kernels in the 203x range are susceptible to blind TCP spoofing attacks due to the way that the kernel handles invalid ack sequence numbers, and the way it assigns IDs to outgoing IP datagrams For this vulnerability to be effective, 3 conditions have to be met: The spoofed machi ...